299,038
Total vulnerabilities in the database
In langgenius/dify v0.10.1, the /forgot-password/resets endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete compromise of the application.
| Software | From | Fixed in |
|---|---|---|
| langgenius / dify | 0.10.1 | 0.10.1.x |